Getting Data In

How to tell what caused overage?

rainhailrob
Path Finder

I was testing Splunk App for *nix before putting it into production. We were consistently getting 30-40Mb/day, but while I was out of the office (14 days), the usage went over the 500Mb limit. I'm trying to determine what caused the overage and by how much before moving to production and having even bigger problems if we go over our 10Gb license.

Apps > Search > Status > Index Activity > Indexing
is displaying less than 100Mb per day.

Any ideas?

0 Karma
1 Solution

jgedeon120
Contributor

Install the Splunk on Splunk app and you will be able to look at more details of your index usage and the sources, sourcetypes to see what/where the increase was caused.

View solution in original post

0 Karma

rainhailrob
Path Finder

I was able to get reset key from Rob, but now when I go to Deployment Monitor > License Report

Usage Summary
Peak daily usage in last 30 days: 0.06 GB
Average daily usage across all days in last 30 days: 0.06 GB
Average usage across top 5 days in last 30 days: 0.06 GB

The Splunk on Splunk Metrics shows the same .06Gb

So now I'm really confused.

0 Karma

jgedeon120
Contributor

Install the Splunk on Splunk app and you will be able to look at more details of your index usage and the sources, sourcetypes to see what/where the increase was caused.

0 Karma
Got questions? Get answers!

Join the Splunk Community Slack to learn, troubleshoot, and make connections with fellow Splunk practitioners in real time!

Meet up IRL or virtually!

Join Splunk User Groups to connect and learn in-person by region or remotely by topic or industry.

Get Updates on the Splunk Community!

May 2026 Splunk Expert Sessions: Security & Observability

Level Up Your Operations: May 2026 Splunk Expert Sessions Whether you are refining your security posture or ...

Network to App: Observability Unlocked [May & June Series]

In today’s digital landscape, your environment is no longer confined to the data center. It spans complex ...

SPL2 Deep Dives, AppDynamics Integrations, SAML Made Simple and Much More on Splunk ...

Splunk Lantern is Splunk’s customer success center that provides practical guidance from Splunk experts on key ...